Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
8.1
CVE-2026-77176
Red Hat · Red Hat OpenShift Container Platform 4

Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy

Description

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator can exploit insufficient validation of CreateContainer mount and storage rules. This allows them to mount arbitrary container-rootfs paths over sensitive host locations or provision arbitrary content, potentially exposing confidential information or enabling the acceptance of attacker-controlled input.

Affected Products

VendorProductVersions
Red HatRed Hat OpenShift Container Platform 4—

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
red hatred hat openshift containermitre_affected90%

References

  • https://access.redhat.com/security/cve/CVE-2026-77176(vdb-entry, x_refsource_REDHAT)
  • https://bugzilla.redhat.com/show_bug.cgi?id=2517502(issue-tracking, x_refsource_REDHAT)
  • https://github.com/kata-containers/kata-containers/security/advisories/GHSA-fmg6-v47x-52wr

Related News (2 articles)

Tier C
oss-security3d ago
CVE-2026-77176: Kata-containers: insufficient validation of createcontainer mount and storage rules in genpolicy
→ No new info (linked only)
Tier C
VulDB3d ago
CVE-2026-77176 | Red Hat Kata Containers genpolicy information disclosure
→ No new info (linked only)
CVSS 3.18.1 NONE
CISA KEV❌ No
Actively exploited❌ No
CWECWE-73
PublishedAug 20, 2026
Last enriched3d ago
Trending Score23
Source articles2
Independent2
Info Completeness6/14
Missing: versions, cvss, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-13595EXP
Util-linux: util-linux: heap use-after-free in libblkid nested partition probing
Trending: 36
NONECVE-2026-18917EXP
Libvirt: integer overflow in nodegetfreepages rpc handler leading to heap buffer overflow
Trending: 35
NONECVE-2026-17523EXP
Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges
Trending: 33
NONECVE-2026-18963
Keycloak-services: keycloak-services: unauthenticated account takeover via reset-credentials flow bypass
Trending: 26
MEDIUMCVE-2026-73199EXP
Ipa: freeipa: null pointer dereference in `ipa-enrollment` extended operation (`join_oid`) via missing request value
Trending: 23

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 20, 2026
Discovered by ZDM
Aug 20, 2026